Microsoft Edge Add-ons Verified

Cometin Desktop

by Stjin
000d8b4d-9a4f-5d94-b8ea-fbdbfca7f874 | v1.0.1.2
53/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v1.0.1.2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

81 detail rows
Showing 25 of 40 · highest severity first

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

2
js/jquery-3.4.1.min.js_metadata/verified_contents.json
Risky Plugins Authors FP 30%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

4
setup/setup.jsjs/jquery-3.4.1.min.jsdashboard/dashboard.js +1 more
FP 5%
HIGHpostinstall file manipulation

File system manipulation detected

17
dashboard/dashboard.jssetup/setup.htmljs/jquery.dataTables.min.js +14 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

3
utils.jsdashboard/help/help.htmljs/jquery-3.4.1.min.js
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

7
background.jsdashboard/general_include.jsjs/jquery-3.4.1.min.js +4 more
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

6
js/bootstrap.bundle.min.jsjs/jquery-3.4.1.min.jsjs/qrcode.min.js +3 more
Risky Plugins Authors FP 20%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

2
js/bootstrap.bundle.min.jsjs/jquery-3.4.1.min.js
FP 10%

Publisher Evidence

Limited evidence

Stjin

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
stjin.host
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

41
Malware Signatures
13
Network

YARA Rules Matched

7 rules(41 hits)
postinstall crypto operations NoUseWeakRandom postinstall file manipulation postinstall system command postinstall network communication postinstall obfuscation SQLInjection

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality weak.

The Cometin Desktop extension presents an ambiguous security profile requiring further investigation. The extension claims to sync PC information with Cometin Cloud, and its network behavior aligns with this stated purpose. Network findings show jquery_ajax calls in background.js:14, background.js:61, background.js:178, dashboard/dashboard.js:15, dashboard/dashboard.js:167, dashboard/general_include.js:12, setup/setup.js:33, and multiple locations in dashboard/notes/notes.js (lines 28, 78, 137, 236, 292). These are legitimate synchronous HTTP calls consistent with a cloud sync extension's functionality.

However, 41 high-severity malware-signature findings create significant concern. The evidence bundle does not specify which YARA rules triggered these findings or what specific code patterns matched. This is a critical gap—without knowing whether these are actual malware signatures or broad false-positive rules (such as the reclassified Bolonyokte, JavaDropper, or Surtr rules that match benign patterns), the risk cannot be properly assessed.

Additional risk factors include: developer name "Stjin" is not a known or verified publisher; user count is 0 indicating no adoption or review history; and version is listed as "unknown" suggesting incomplete metadata collection. The extension claims to be "official" Cometin Desktop but Cometin is not a well-known service, making impersonation unverifiable.

The strongest counterargument for a benign verdict is that the network findings show no suspicious domains, no credential access patterns, no obfuscation, and no IoC matches—all network calls are standard jquery AJAX for cloud communication. A skeptic would argue that 41 malware signatures in a 0-user extension from an unknown developer represents clear malicious intent. However, without signature specificity, this conclusion cannot be drawn. The malware-signature findings could stem from bundled libraries triggering broad YARA rules, which would make this a false positive rather than actual malware.

Runtime analysis or manual code review is required to determine whether the malware-signature findings represent genuine threats or known false-positive patterns.

Key Reasons

  • 41 high-severity malware-signature findings without specific rule details
  • Unknown developer (Stjin) with 0 users and unknown version
  • Network behavior appears benign (jquery AJAX for cloud sync)
  • No obfuscation, no IoC matches, no suspicious domains detected
  • Missing malware-signature specificity prevents definitive verdict

False Positive Considerations

  • Malware-signature findings lack rule specificity
  • May be triggered by bundled library patterns

Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 55%.

Frequently Asked Questions